Privacy & practical tips

What private browser-based file processing means

Understand the difference between local file processing and website traffic, and review your downloads before sharing them.

Selecting a file is not the same as uploading it

A web page can use browser file APIs to read a file you choose, work on it locally and create a downloadable result. The current asdftools file tools follow that approach: your selected source files are processed on your device rather than sent to the application server or an external AI service.

This is a statement about these tools, not every website with a file picker. Other services may upload selected files immediately. Read the processing notice for the tool you are using, especially when moving between different websites or future features.

Local processing does not mean no network activity

Your browser still requests web pages, scripts, styles and images so the website can load. Ordinary server access logs can record an IP address, requested URL and request time. These visit records are separate from the contents of a file you select in the workspace.

Do not put private document text, access tokens or passwords into a page URL or search query. Local processing is not a claim of anonymous browsing, zero server logs or guaranteed offline availability. Consult the privacy page for the current description of website data handling.

Your device remains part of the security boundary

A local workflow avoids transferring the original to a conversion server, but it does not make an unsafe device safe. Browser extensions, other people using your computer, malware, downloads and cloud-synced folders can affect confidentiality. Use an updated browser on a trusted device, and follow any workplace rules for sensitive documents.

Large inputs also consume device memory. If a task cannot finish, try fewer files or smaller copies rather than repeatedly opening large jobs in new tabs. Keep originals outside the workspace so a failed conversion does not leave you without a usable source.

Inspect the content, not just the file name

Open a downloaded image or PDF before sending it. Look for visible personal details as well as document properties. The PDF metadata viewer shows common fields and page information; it is not a forensic audit, malware scanner or complete metadata-removal tool.

Likewise, the SHA-256 tool hashes UTF-8 text, not uploaded files. A digest is not encryption or proof of who wrote the text. Do not paste a secret simply to make it look unreadable, and do not treat a black rectangle over a PDF page as verified permanent redaction.

Finish with a deliberate handoff

Save the reviewed output to a location you control, reset the workspace when finished and close the tab on a shared device. These actions are useful housekeeping, not a promise of secure erasure from browser memory or device storage. Downloads and their backups remain your responsibility after the task.

  • Check whether your downloads folder is shared or cloud-synced.
  • Choose the intended file and recipient before sharing.
  • Use a dedicated, approved workflow when a document requires stronger controls.

Further reading